note 9364 deleted from ref.pdf by didou
| From: | didou@php.net | Date: | Sat, 09 Aug 2003 03:27:42 +0000 |
| Subject: | note 9364 deleted from ref.pdf by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-53725@lists.php.net to get a copy of this message | ||
Note Submitter: mike_nospam@envisionsoftware.co.nz
----
[Editor's note: See the section "Security" in the manual for more information on this
and other security matters]
The script getpdf.php should only be used to learn the concept of passing a file through a script
and not actually used to perform this task. In its current state, there is a large security flaw
which enables many files (including all your php source) to be viewed by anyone.
For example http://server/getpdf.php?filename=/etc/passwd
shows the servers machines password file.